CVE-2025-59669: Medium severity Fortinet FortiWeb vulnerability
A use of hard-coded credentials vulnerability in Fortinet FortiWeb 7.6.0, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, FortiWeb 7.0 all versions may allow an authenticated attacker with shell access to the device to connect to redis service and access its data
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-59669?
CVE-2025-59669 is considered a high-severity vulnerability due to the potential for unauthorized access to sensitive data.
How do I fix CVE-2025-59669?
To mitigate CVE-2025-59669, update FortiWeb to the latest version available from Fortinet that addresses this vulnerability.
Who is affected by CVE-2025-59669?
CVE-2025-59669 affects users of Fortinet FortiWeb version 7.6.0 and all versions of 7.4, 7.2, and 7.0.
What type of vulnerability is CVE-2025-59669?
CVE-2025-59669 is a use of hard-coded credentials vulnerability that allows authenticated attackers to access the redis service.
Can CVE-2025-59669 be exploited remotely?
CVE-2025-59669 requires authenticated shell access to the affected device to exploit the vulnerability.